Aller au contenu principal
Retour à la base de rançongiciels
Groupe de rançongiciel

darkside

Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.

Victimes connues10

Niveau de menace

FAIBLE

Tactiques, techniques et procédures (TTP)

CredentialTheft

  • Mimikatz
  • SessionGopher

DiscoveryEnum

  • ADRecon
  • AdFind
  • Advanced IP Scanner
  • SoftPerfect NetScan

Exfiltration

  • Bashupload
  • MEGA
  • RClone
  • Sendspace
  • pCloud

LOLBAS

  • PsExec

Networking

  • Plink

Offsec

  • Cobalt Strike
  • CrackMapExec
  • Impacket
  • PowerSploit

RMM-Tools

  • AnyDesk
  • GoToAssist
  • TightVNC
0

Vérifier si vous êtes touché

Cherchez dans notre base si votre organisation figure sur la liste des victimes de darkside.

Essayez maintenantGratuit⌘K
Exemple

score de risque · catégories de menace · sources · ancienneté · confiance — en une requête

Autres groupes de rançongiciel actifs